Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.4 CVE-2024-29834 This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u… Pulsar 3.0.4 / 3.2.2+ Fix from $1,6002024-04-02 MEDIUM 6.5 CVE-2024-31134 In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was dis… Teamcity 2024.03+ Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2024-23451 Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.… Elasticsearch 8.13.0+ Fix from $1,6002024-03-27 HIGH 7.4 CVE-2023-6400 Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue aff… Mitigation only Fix from $1,9502024-03-27 HIGH 8.8 CVE-2024-2915 Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation featu… Devolutions Server 2024.1.8.0+ Fix from $1,9502024-03-26 HIGH 8.8 CVE-2024-27933 Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature … Deno Patch available Fix from $1,9502024-03-21 MEDIUM 6.5 CVE-2024-27105 Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, gra… Frappe 14.66.3 / 15.16.0+ Fix from $1,6002024-03-21 HIGH 8.8 CVE-2023-49982 Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perf… School Fees Management System No fix yet Fix from $1,9502024-03-21 MEDIUM 6.5 CVE-2023-50811 An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific … Visual Access Manager Mitigation only Fix from $1,6002024-03-19 CRITICAL 9.8 CVE-2024-28394 An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistic… Mitigation only Fix from $2,3002024-03-19 CRITICAL 9.1 CVE-2024-2557 A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of… Food Waste Management System No fix yet Fix from $2,3002024-03-17 HIGH 8.0 CVE-2023-50886 Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7. Legal Pages 1.3.8+ Fix from $1,9502024-03-15 MEDIUM 6.5 CVE-2024-23823 vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Comput… Vantage6 4.2.1+ Fix from $1,6002024-03-14 MEDIUM 6.4 CVE-2023-50726 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov… Argo Cd 2.8.12 / 2.9.7+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1479 The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_displ… Wp Show Posts 1.1.5+ Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-28098 The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off… Pulsar 2.10.6 / 2.11.4+ Fix from $1,6002024-03-12 MEDIUM 5.5 CVE-2023-45793 A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of … Siveillance Control 3.1.1+ Fix from $1,6002024-03-12 MEDIUM 6.5 CVE-2024-22133 SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou… Fiori Front End Server Mitigation only Fix from $1,6002024-03-12 MEDIUM 5.5 CVE-2024-23250 An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watch… Ipad Os 10.4 / 14.4+ Fix from $1,6002024-03-08 MEDIUM 6.5 CVE-2024-28229 In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles Youtrack 2024.1.25893+ Fix from $1,6002024-03-07 HIGH 8.0 CVE-2024-0199 An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 1… GitLab 16.7.7 / 16.8.4+ Fix from $1,9502024-03-07 HIGH 8.1 CVE-2024-27915 Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of ro… Sulu 2.4.17 / 2.5.13+ Fix from $1,9502024-03-06 HIGH 7.5 CVE-2024-24761 Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages a… Galette Patch available Fix from $1,9502024-03-06 MEDIUM 5.8 CVE-2024-28174 In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly Teamcity 2023.11.4+ Fix from $1,6002024-03-06 HIGH 7.5 CVE-2024-27139 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated… Archiva Mitigation only Fix from $1,9502024-03-01 HIGH 7.5 CVE-2024-27138 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, … Archiva Mitigation only Fix from $1,9502024-03-01 HIGH 8.8 CVE-2023-47716 IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual… Cp4ba Filenet Content Manager Mitigation only Fix from $1,9502024-03-01 MEDIUM 5.8 CVE-2024-20291 A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon… Nx Os Mitigation only Fix from $1,6002024-02-29 CRITICAL 9.1 CVE-2024-25170 An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. Mezzanine No fix yet Fix from $2,3002024-02-28 MEDIUM 6.5 CVE-2024-24773 Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apa… Superset 3.0.4 / 3.1.1+ Fix from $1,6002024-02-28